SQL Injection Vulnerability in Project Management WordPress Plugin
CVE-2026-12877
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2026
Badges
What is CVE-2026-12877?
The Project Management, Bug and Issue Tracking Plugin for WordPress, prior to version 5.1.0, is susceptible to SQL injection due to inadequate sanitization and escaping of user-supplied input in SQL queries. This vulnerability allows unauthenticated attackers to manipulate database queries, potentially leading to unauthorized data access or alteration. The flaw is particularly concerning when the plugin's front-end issue tracker is misconfigured, making it an attractive target for exploitation.
Affected Version(s)
Project Management, Bug and Issue Tracking Plugin 0 < 5.1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.